首页> 外文会议> >Implementing transaction control expressions by checking for absence of access rights
【24h】

Implementing transaction control expressions by checking for absence of access rights

机译:通过检查是否缺少访问权限来实现事务控制表达式

获取原文

摘要

Separation of duties is an important, real-world requirement that access control models should support. The transaction control expression (TCE) for specifying dynamic separation of duties was previously introduced. The implementation of TCEs in the typed access matrix model (TAM) is considered. It is shown that TAM requires extension for satisfactory handling of dynamic separation of duties. In particular, dynamic separation requires the capability to explicitly test for the absence of rights in cells of the access matrix. It is illustrated how TAM, extended to incorporate such tests, can implement TCEs. The impact of checks for absence of rights on safety analysis is discussed (i.e. the determination of whether or not a given subject can acquire a given right to a given object).
机译:职责分离是访问控制模型应支持的一项重要的现实需求。先前引入了用于指定动态职责分离的事务控制表达式(TCE)。考虑了在类型化访问矩阵模型(TAM)中TCE的实现。结果表明,TAM需要扩展才能令人满意地处理动态职责分离。特别地,动态分离要求能够明确测试访问矩阵的单元中是否没有权限。它说明了扩展到包含此类测试的TAM如何实现TCE。讨论了检查缺少权限对安全性分析的影响(即确定给定对象是否可以获取给定对象的给定权限)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号